CVE-2026-14231: Unknown Lifterlms
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its select2 query AJAX handlers, only verifying that the user is logged in, allowing any authenticated user with subscriber-level access to read the titles of internal post types such as coupon codes by supplying the post type.
Affected products
- Unknown Lifterlms: before 10.0.10 (fixed in 10.0.10)
Published 2026-07-30. Last modified 2026-07-30.